Thread

🛡️
Introducing... Vault - NOSTR Password Manager A free, open source, and decentralized password manager. Download extension: https://chrome.google.com/webstore/detail/vault-password-manager-on/namadahddjnkmjgdnncdlhioopmjiflm Source code: -- == -- More info: Vault utilizes zero-knowledge encryption to safeguard your data while storing it on NOSTR network for enhanced resilience. Vault saves all your passwords and notes securely by encrypting your data twice; once with your secret key and once with your passcode. Your data are not stored on any centralized server, but rather on a set of relay servers. This means that it is resilient to attacks and that you are the only one who can access your passwords. Security experts recommend that you use a different, randomly generated password for every account that you create, and Vault makes this easy. Vault can generate passwords and store them for you, this means that you only need to remember one password, your passcode. Looking to store and swiftly retrieve your data? Vaults facilitate searchable items, allowing you to effortlessly copy the desired information with a single click. Vault is free, open source, and decentralized; and will always be. -- == -- Status and questions: - Version 1.0.0 approved on Chrome Web Store. Version 1.0.1 is the real version I wanna push to you guys, might have to wait for 24 hours for approval - Enhanced Safe Browsing? - Apparently for new developers, it generally takes a few months to become trusted. - Read history? - not really, just that need to read what page you are currently on and paste the URL when you add new items -- == -- @The Nostr Report @jb55 @ODELL @Gigi @fiatjaf @jack @Derek Ross

Replies (33)

Great works @Jingles doing "other stuff" in Nostr :) Maybe this is just a bit of idea, you can probably offer dedicated relay as server (like BitWarden) and also with custom relay setting for user who want to self host on their own private relay. Additionally, you can also use NIP-42 auth if the relay support it to make sure only specific user can access safely. :)
Nice. Yes, some relays implementation have supported NIP-42 authentication which protecting event from unauthorized read (only whitelisted pubkey can read). We can check their support based on NIP-11 information. I think nostr-tools library already suppport NIP-42, so for certain relays you can probably utilize it to make it more secure.
🛡️
image Things are getting bigger so I chickened and decided to reduce the reward to 100,000 sats If you hack its vault successfully, you’ll get 12 word seed phrase to access 2 utxo with total 100,000 sats I hope this amount will be enough to bring active attacker to that account. Ps. I’ve setup the account with different nostr private key on the laptop that I’m going to factory reset it, just to make sure that the attacker must aim their ion cannons to the vault’s backend/cloud or anything thats store the data and not from the user side and I’m not a techy guys I don’t want my laptop being targeted by bunch of hackers 😂 Good luck challenger ! Also, I will notify on this post again when I bored and decide to withdraw the reward.